Loading...
Most teams we are called in to help have contained less than they think, and identified the wrong way in. Forensics settles both -- and produces a record that holds up afterwards with regulators, insurers, and counsel.

The most common thing we find on arrival is that the incident is not contained. A team under pressure isolates what it knows about, reports the incident closed, and moves to recovery -- while the access that mattered is still live. In one recent engagement roughly a fifth of the affected footprint had actually been contained by the time we were brought in. Establishing what is genuinely cut off, and what is still reachable, is the first thing forensics buys you, and it is worth more in that moment than any report.
The second is root cause. Teams reason backwards from the alert that fired and land on a plausible entry point, which is not always the real one. In one recent case the assumed attack vector turned out to be entirely different from the actual one -- and remediation aimed at the assumed vector would have left the real path open while everyone believed the matter was closed. You cannot durably fix what you have misidentified.
If you are mid-incident, contain first. Cut off active access, rotate credentials you believe are compromised, and isolate what needs isolating -- an attacker still holding valid credentials is a worse problem than an incomplete investigation, and nothing on this page should delay that. Preservation runs alongside containment, not after it. What genuinely destroys evidence is the step after containment: re-imaging the host, wiping the disk, or letting a log source age out. Snapshot before you rebuild, and check the retention windows on CloudTrail, VPC Flow Logs, and your EDR before they roll. Call while you are doing it -- the preservation conversation is free and time-critical in a way the rest of the engagement is not.
Because the work is run to chain-of-custody discipline -- documented acquisition, hashes recorded at collection, an auditable record of who touched what and when -- the same investigation that drives containment also stands up later with a regulator, a cyber insurer, an acquirer, or opposing counsel. That matters most when the question is whether you are obliged to notify. Two recent engagements, both in regulated industries with statutory reporting duties and one in healthcare, produced a factual record precise enough that counsel could conclude no notification obligation had been triggered. In the healthcare matter the potential blast radius ran to terabytes of patient data; without evidence at that standard, counsel would have had no basis except to assume the worst.
The written report states what was accessed, by whom, over what window, by what route -- and what the evidence does not support. We are deliberate about that last part, because an investigation that overstates its certainty is worse than useless in a dispute. Questions the evidence cannot answer are stated as such, with what would have been needed to answer them.
We also work with organisations who are not in an incident. Forensic readiness is unglamorous and cheap by comparison: logging that retains what an investigation would actually need, an agreed preservation procedure, and a relationship already in place so the first call is not also the first conversation.

Engineering rigor, audit-ready process, and operational depth across cloud, SaaS, and software delivery
Incidents are routinely reported contained while the access that mattered is still live. We establish what is genuinely cut off and what is still reachable -- the finding that changes what you do in the next hour.

Teams reason backwards from the alert that fired and land on a plausible entry point. When it is the wrong one, remediation leaves the real path open while everyone believes it is closed. We identify the vector from evidence, not inference.

Chain-of-custody discipline and timeline reconstruction from CloudTrail, VPC Flow Logs, EDR telemetry, identity logs, and application audit trails -- precise enough for counsel to reason about notification duties instead of assuming the worst.

Preserve, verify containment, establish root cause, then report in a form that survives challenge.
Containment is never held up for evidence. While access is being cut off, we snapshot volumes, capture memory where it is still available, freeze log retention that is about to roll off, and document what was taken and when. The two run together: the destructive step to avoid is rebuilding a host before it has been imaged, not cutting off an attacker.
Before the analysis proper: what is actually cut off, and what is still reachable. Incidents are frequently reported contained while live access persists, so this runs early and its findings are actionable the same day rather than at report time.
Forensic images acquired with documented handling and recorded hashes. Analysis establishes the real entry vector rather than the assumed one, plus blast radius, persistence, lateral movement, and whether data was exfiltrated or merely exposed -- a distinction that often decides notification obligations.
A written report stating findings, the evidence each rests on, and the limits of what the evidence supports. Written to be read by counsel, a regulator, or an insurer -- not only by engineers. We will walk your stakeholders through it.
What the investigation revealed about your logging, retention, and containment usually matters more than the incident itself. We turn that into concrete remediation, and where you want it, a readiness posture so the next investigation starts from a better position.
Containment is never held up for evidence. While access is being cut off, we snapshot volumes, capture memory where it is still available, freeze log retention that is about to roll off, and document what was taken and when. The two run together: the destructive step to avoid is rebuilding a host before it has been imaged, not cutting off an attacker.
Before the analysis proper: what is actually cut off, and what is still reachable. Incidents are frequently reported contained while live access persists, so this runs early and its findings are actionable the same day rather than at report time.
Forensic images acquired with documented handling and recorded hashes. Analysis establishes the real entry vector rather than the assumed one, plus blast radius, persistence, lateral movement, and whether data was exfiltrated or merely exposed -- a distinction that often decides notification obligations.
A written report stating findings, the evidence each rests on, and the limits of what the evidence supports. Written to be read by counsel, a regulator, or an insurer -- not only by engineers. We will walk your stakeholders through it.
What the investigation revealed about your logging, retention, and containment usually matters more than the incident itself. We turn that into concrete remediation, and where you want it, a readiness posture so the next investigation starts from a better position.
The difference only becomes visible when someone challenges the findings.
| Feature | Handled internally, under pressure | Forensic investigation |
|---|---|---|
| Containment | Declared closed once the known-affected systems are isolated | Verified against evidence -- what is genuinely cut off, and what is still reachable |
| Root Cause | Inferred backwards from the alert that fired | Established from evidence, including when it contradicts the assumed vector |
| Evidence Handling | Hosts rebuilt and disks wiped before anything is captured | Containment and preservation run in parallel, with documented acquisition and recorded hashes |
| Defensibility | Findings rest on recollection and screenshots | Findings rest on preserved evidence with an auditable custody record |
| Scope of Answer | "We think they got in through the VPN" | Access path, window, blast radius, and exfiltration-versus-exposure, each tied to evidence |
| Uncertainty | Gaps discovered later, by the party challenging you | Gaps stated in the report, with what would have been needed to close them |
Forensics is usually filed under post-incident paperwork. In practice it does its most valuable work during Respond -- verifying that containment is real and that the vector you are remediating is the actual one.
| Previous lifecycle phase (SP 800-61r2) | CSF 2.0 Function (SP 800-61r3) | What forensic capability contributes |
|---|---|---|
| Preparation | Govern · Identify · Protect | Forensic readiness: retention and logging that hold what an investigation would actually need, an agreed preservation procedure, evidence-source inventory, and an engagement in place so the first call is not also the first conversation. Cheap here, impossible to retrofit mid-incident. |
| Detection & Analysis | Detect · Identify (Improvement) | Establishing the real entry vector rather than the one inferred backwards from the alert that fired, and scoping the access path, persistence, and lateral movement from evidence rather than assumption. |
| Containment, Eradication & Recovery | Respond · Recover · Identify (Improvement) | Verifying containment is genuine and not merely declared, confirming eradication removed persistence rather than the symptom, preserving evidence before remediation destroys it, and giving counsel a factual basis for whether notification duties are triggered. Recovery proceeds knowing the restore is clean and the path is closed. |
| Post-Incident Activity | Identify (Improvement) | The written report, plus what the investigation revealed about your logging and retention -- which is usually the finding with the longest shelf life, because it determines what the next investigation will be able to answer. |
SP 800-61r3 (April 2025) supersedes r2 and reorganises incident response around the six CSF 2.0 Functions; the four phases above are r2's model, which r3 retains as a crosswalk in its Table 1. Both vocabularies are shown because auditors and insurers still ask in either. NIST's own guidance is that organizations should use whichever lifecycle model suits them best.
What organisations and their counsel ask, usually in a hurry.
Buyers of digital forensics & incident investigation typically partner with us across these adjacent disciplines
Detection shortens the window an investigation has to reconstruct -- and produces the telemetry the investigation depends on.
An investigation tells you how they got in; a pen test tells you where else they could have.
Breach notification obligations live inside your compliance program. What an investigation finds determines what you are required to disclose.
If you are mid-incident, contain first and call while you are doing it -- the preservation conversation is free, and verifying containment is usually the fastest thing we can do for you. If you are planning ahead, a readiness engagement puts the logging and the relationship in place first.